HIGH🇵🇱 Wersja polska

CVE-2022-31670

CVSS 7.7v3.1pub. 2024-11-14upd. 2024-11-19

Harbor fails to validate the user permissions when updating tag retention policies.  By sending a request to update a tag retention policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag retention policies configured in other projects.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
  • Linuxfoundation Harbor

    APP
    Linuxfoundation
    1.0.0 – 1.10.13 (excl.)2.0.0 – 2.4.3 (excl.)2.5.0 – 2.5.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-4404CRITICAL9.4PL ✓same product

Hardkodowane dane uwierzytelniające w GoHarbor Harbor — nieautoryzowany dostęp do panelu

CVE-2022-31666HIGH7.7same product

Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, u...

CVE-2022-31668HIGH7.4same product

Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to upda...

CVE-2022-31671HIGH7.4same product

Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat...

CVE-2022-46463HIGH7.5same product

An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image reposit...